Nebraska · NDPA

Nebraska privacy law, explained for practice owners

No threshold. Small businesses mostly exempt. One rule survives anyway.

Mostly exempt — with one live obligation In effect since January 1, 2025 HIPAA exemption: entity-level Reviewed July 25, 2026

The short answer

Nebraska has no volume threshold. Instead it exempts small businesses as defined by the Small Business Administration, and it exempts HIPAA covered entities at the entity level — so most practices are out of scope twice over. Except for one provision that Nebraska deliberately left standing even for exempt small businesses: you may not sell sensitive data without consent. Health data is sensitive data, and Nebraska defines “sale” to include exchanges for other valuable consideration. That single surviving rule is the one most likely to be triggered by the advertising tags on a practice website.

In effect sinceJanuary 1, 2025
Applies atNo volume threshold —
SBA small-business test
Max penaltyUp to $7,500
per violation
Cure period30 days
(no sunset)

The scan loads your site in a real browser and reports which trackers fire before any consent is given. No signup.

Scope

Does NDPA actually apply to your practice?

Three questions, in order. Most practices can answer the first one and stop — but almost none have answered it in writing.

1

Are you a HIPAA covered entity?

If yes, NDPA does not apply to you at all — Nebraska exempts covered entities and business associates at the entity level, not just their patient records.

If you have never had that determination made in writing, treat it as unanswered. A provider who never transmits a HIPAA standard transaction electronically may not be a covered entity.

2

If not, do you cross the threshold?

Without the entity-level exemption, the applicability test is the only thing between you and the statute. No volume threshold — SBA small-business test.

Count website visitors, not just patients. Personal data includes the identifiers your site collects.

3

Either way, three things still bind you

HIPAA and the federal analysis of tracking technologies. Other states whose residents visit your one website. And your own published privacy policy, which becomes a consumer-protection problem the moment it stops describing what your site actually does.

No state privacy exemption reaches any of those three.

Reference

Nebraska privacy law: the key facts

Nebraska Data Privacy Act (NDPA), Neb. Rev. Stat. § 87-1101 et seq.. Last reviewed July 25, 2026 against the statute text and the enforcing agency's own material.
LawNebraska Data Privacy Act (NDPA)
CitationNeb. Rev. Stat. § 87-1101 et seq.
EffectiveJanuary 1, 2025
One of only two states with no data-volume threshold at all. Applicability turns on small-business status instead.
Who enforces itAttorney General (exclusive)
Applicability

Nebraska took the Texas approach and threw out volume thresholds entirely. The NDPA applies to any person that:

  • conducts business in Nebraska or produces a product or service consumed by Nebraska residents;
  • processes or engages in the sale of personal data; and
  • is not a small business as defined under the federal Small Business Act.

The SBA definition is industry-specific by NAICS code, commonly fewer than 500 employees, sometimes framed as a revenue ceiling. Most independent medical practices are small businesses under it. That is the good news.

The bad news is in the next paragraph, and it is the entire reason this page exists.

HIPAA exemption

Entity-level — a HIPAA covered entity is outside the statute

Nebraska exempts HIPAA covered entities and business associates at the entity level, along with PHI and HIPAA de-identified data. Combined with the small-business exemption, most practices are outside the bulk of the NDPA on two independent grounds.

But note which obligation survives the small-business exemption — it is not a general one, and it is aimed precisely at how medical websites work.

Sensitive data

Sensitive data requires opt-in consent, and includes data revealing a mental or physical health diagnosis, racial or ethnic origin, religious beliefs, sexual orientation, citizenship or immigration status, genetic and biometric data, precise geolocation, and data of a known child.

And this is the one rule that follows a small business: even an exempt small business may not sell sensitive data without the consumer's consent.

Definition of “sale”

Broad — monetary or other valuable consideration

Nebraska uses the broad definition: a sale is a disclosure for monetary or other valuable consideration. This is the piece that makes the surviving small-business obligation bite, because advertising data sharing is the canonical example of other valuable consideration.

Universal opt-out / GPC

Yes, for controllers subject to the Act. Nebraska requires recognition of a universal opt-out mechanism.

Consumer rights
  • Access, correction, deletion, and portability
  • Opt out of sale, targeted advertising, and consequential profiling
  • Consent required before processing sensitive data
  • Appeal a denied request
  • For exempt small businesses: only the sensitive-data sale consent requirement applies
Cure period

Nebraska provides a 30-day cure period with no expiration. The Attorney General must give written notice identifying the specific provisions at issue and allow thirty days to fix the problem.

Penalties

Up to $7,500 per violation under Nebraska's Consumer Protection Act, plus injunctive relief and the Attorney General's expenses, available after the cure window closes.

Private right of action

No private right of action. Exclusive enforcement by the Nebraska Attorney General.

What it means for you

The parts that actually change how you operate

The exemption that keeps the one rule aimed at you

This is the whole Nebraska story, and it is worth being precise about because the structure is counterintuitive.

Step one: Nebraska has no 100,000-consumer threshold. Anyone processing personal data is potentially in scope.

Step two: Nebraska exempts small businesses under the federal Small Business Act. Nearly every independent practice qualifies.

Step three: Nebraska carves back into that exemption, and keeps in force the prohibition on selling sensitive data without consent.

Now overlay a medical practice. Sensitive data includes data revealing a mental or physical health diagnosis. “Sale” includes disclosure for other valuable consideration. A remarketing tag on a treatment page discloses visitor identifiers to an advertising platform, and the consideration is better ad performance.

Whether any specific tag crosses that line depends on what it actually transmits, and that is a question for counsel looking at your actual configuration. But the shape is unmistakable: of everything Nebraska could have kept applicable to small businesses, it kept the provision that maps most directly onto healthcare advertising.

Why the entity-level exemption is the stronger card

Because the small-business exemption has that carve-back and the HIPAA entity-level exemption does not, your covered-entity status is the more valuable protection in Nebraska.

Which means the same determination that matters everywhere else matters here too: is your practice a health plan, a healthcare clearinghouse, or a provider that transmits health information electronically in connection with a HIPAA standard transaction? A cash-pay practice that never submits electronic claims may not be — and would then be relying solely on the small-business exemption, which is exactly the one with the health-data hole in it.

Practical posture for a Nebraska practice

Short version: do not build a full state-privacy compliance program for Nebraska. Do make sure of three things.

  1. Your covered-entity status is determined and documented.
  2. No third-party tag transmits anything revealing a health condition without prior consent — because that is the one obligation that reaches you either way.
  3. You can produce a record showing when consent was captured.

All three are the same controls the stricter states require, so the marginal cost of covering Nebraska properly is close to zero.

Where the risk lives

Your website is the exposed surface, not your chart system

Practices spend their compliance budget on the EHR, because that is where the patient records are. But the EHR is inside a HIPAA framework with a business associate agreement, access controls, and an audit log. It is the most governed system you own.

Your website is the least governed. Tags accumulate over years, added by successive agencies, and nobody keeps a list. Every one of them is a third party receiving data about someone who came to your site to read about a medical procedure.

That is the gap every state on this list is aimed at, and it is the gap the federal tracking-technology analysis is aimed at too.

What a regulator or a plaintiff can check without asking you anything

  • Which third-party scripts load on your consult and treatment pages, and whether any of them fire before a visitor interacts with your banner.
  • Whether your site responds to a Global Privacy Control signal.
  • Whether the opt-out your privacy policy describes actually exists and actually works.
  • Whether your privacy policy's claims match your site's behavior.

All four are testable from outside your building, in a few minutes, with a browser. That asymmetry is the reason website privacy became an enforcement priority: it is the rare compliance question a regulator can answer before opening a file.

The federal floor, stated accurately

HHS Office for Civil Rights issued guidance on tracking technologies in December 2022 and revised it in March 2024. In American Hospital Association v. Becerra (June 2024) a federal court vacated part of that guidance, and HHS withdrew its appeal — so OCR's specific theory that metadata such as an IP address collected on an unauthenticated public page is automatically individually identifiable health information no longer stands.

What survived matters more than what did not. The HIPAA Privacy Rule itself was untouched. Authenticated environments, patient portals, and any context where a specific individual's care can be inferred remain squarely inside the analysis. And a marketing vendor that receives identifiable information about a patient's care still needs a business associate agreement or an authorization.

Anyone telling you the court decision made website trackers a non-issue for healthcare has read the headline and not the opinion.

Consequences

What it costs when it goes wrong in Nebraska

Up to $7,500 per violation under Nebraska's Consumer Protection Act, plus injunctive relief and the Attorney General's expenses, available after the cure window closes.

The arithmetic nobody puts in a proposal

For a small-business practice, the realistic Nebraska exposure narrows to one question: did you sell sensitive data without consent. If the answer is no, the NDPA is largely academic for you. If the answer is arguably yes because of what your ad tags transmit, the small-business exemption does not help at all.

The small-business exemption reads like “you're fine.” It isn't quite.

An owner who confirms small-business status and stops there has skipped the sentence Nebraska wrote specifically to survive that status.

The prohibition on selling sensitive data without consent does not care that you are small. And in a state with a broad sale definition and health data in the sensitive category, that is the one provision a practice website is most likely to trip.

Do this

Your Nebraska action list

In order. Items one and two are the ones that change your answer to everything else.

  1. Confirm your SBA small-business status by NAICS code — the definition is industry-specific, not a flat 500-employee rule.
  2. Confirm your HIPAA covered-entity status in writing; it is the stronger exemption here because it has no health-data carve-back.
  3. Do not let any tag transmit health-revealing data to a third party without prior consent, regardless of your exemptions.
  4. Treat advertising data sharing as potentially a “sale” — Nebraska uses the broad definition.
  5. If not exempt, honor universal opt-out signals; required since January 1, 2025.
  6. Keep the 30-day cure period usable by monitoring the address where legal notice arrives.
  7. Maintain timestamped consent records as evidence of what was captured and when.
  8. Have counsel look at your actual tag configuration, not your privacy policy's description of it.

Questions

Nebraska privacy law FAQ

Does the Nebraska Data Privacy Act have a threshold?

No volume threshold. It applies to any person doing business in Nebraska or serving Nebraska residents that processes or sells personal data and is not a small business as defined under the federal Small Business Act.

Are small businesses exempt from the Nebraska Data Privacy Act?

Mostly, but not completely. The exemption leaves one obligation in force: an exempt small business still may not sell a consumer's sensitive data without consent. Because health data is sensitive data and Nebraska defines “sale” broadly, this is the provision most likely to reach a medical practice's website.

Are HIPAA covered entities exempt in Nebraska?

Yes, at the entity level. Nebraska exempts HIPAA covered entities and business associates from the statute, along with PHI and HIPAA de-identified data.

Does Nebraska have a cure period?

Yes, 30 days after written notice from the Attorney General identifying the specific provisions at issue, with no sunset date.

What is the penalty under the NDPA?

Up to $7,500 per violation under Nebraska's Consumer Protection Act, plus injunctive relief and the Attorney General's expenses, after the cure window closes. There is no private right of action.

Verify it yourself

Official sources

Every figure on this page comes from the statute or the office that enforces it. Read them directly — and bring them to your own counsel.

Last reviewed July 25, 2026. State privacy law changes on a rolling basis; amendments in Nebraska and elsewhere are frequent. If you are making a decision that depends on a specific figure, confirm it against the linked source and your counsel rather than against this page.

Honest about the legal layer

Consential is compliance infrastructure. We build and operate the machinery: blocking non-essential tracking until a visitor agrees, detecting which state framework applies, and writing every choice to an append-only record you can produce later.

We are not a law firm, we do not provide legal advice, and using Consential does not by itself guarantee compliance with any state or federal regulation. This page is a plain-language summary of publicly available law, not an opinion on your practice. The determinations that matter most here — whether you are a HIPAA covered entity, whether a specific data flow is a “sale,” whether a given page needs consent — are legal judgments about your specific facts. Get them from healthcare counsel. We pair with your counsel, not in place of them.

Find out what your site is doing right now

Enter your domain. We load it in a real browser and report every tracker that fires before consent, which cookies get set, and whether a consent layer is present at all — scored, with the evidence named.

Scan your site free No signup. Results in about a minute. The scan reports what we observe; it is not a legal opinion.

The rest of the map

Privacy law in the other 19 states

Your website has one configuration for every visitor. If you draw patients across state lines, the strictest state in your traffic sets your standard — not the state you practice in.

Back to state privacy detection · How the consent layer works · Pricing